Cointime

Download App
iOS & Android

CertiK Report: OpenSea Phishing Incident Analysis

Validated Project

Introduction

Back in February 2022, OpenSea users were targeted by an elaborate phishing attack through emails that tricked users into signing permissions with a malicious contract. In total, 28 wallets had NFTs stolen that were worth $2 million making it the second most profitable NFT phishing attack in 2022, just behind the Bored Ape Yacht Club (BAYC) Instagram compromise in April 2022.

Event Summary

On 20 February 2022, multiple OpenSea users realized that their NFTs were being transferred out of their wallets and into the wallet of an unknown user. As far as the victims were aware, they hadn’t signed any permissions allowing for the transfer of NFTs. This was particularly concerning considering OpenSea had recently updated the community that they had to migrate their listings.

Users became suspicious that perhaps the new Wyvern 2.3 contract contained a vulnerability, or there may have been a compromise on OpenSea’s main website. However, as only a few individuals were affected those suspicions shifted to a more targeted approach against specific victims. It soon became clear that a phishing email had been sent to multiple victims.

An email from OpenSea advising on migrating listings wasn’t necessarily an unexpected communication to receive. This was a relatively sophisticated phishing campaign as it not only created a sense of urgency within the reader, common among many phishing scams, but it also contained a direct copy/paste text from OpenSea’s Tweet.

Clicking on the link in an email presented the victim with a phishing site, further prompting them to sign an approval which then allowed the attacker to transfer NFTs out of the victims' wallet.

On Chain Analysis

When signing the aforementioned approval, the victims send an AtomicMatch request to the hacker's malicious contract. From there, the AtomicMatch is sent to the Wyvern Exchange contract, confirming the legitimacy of the signed owner’s approval to transfer the NFT. The NFT is then transferred to the exploiters wallet for 0 ETH.

In total, 28 EOAs fell victim to this phishing exploit. A few examples of valuable NFTs stolen were the 2x BAYC and 3x Mutant Ape Yacht Club NFTs. The full list can be seen in the appendix below.

In total, the malicious actor deposited 1105 ETH into Tornado Cash, worth approximately $2.7 million at the time.

OpenSea Warns Users of Future Phishing Attempts

In August, OpenSea issued a warning to its users to be on the lookout for potential phishing emails following a data leak. The NFT exchange detailed that an employee at customer.io misused their company access to download OpenSea users emails which were used by customers to sign up for OpenSea’s newsletter. Due to the phishing attack in February, OpenSea were prepared to inform their users of potential phishing emails promptly.

In late August, an email was sent to OpenSea customers prompting them to recover their MetaMask account by entering their seed phrase. The site mimicked the MetaMask plug-in which was evident by opening the legitimate extension.

This is a slightly different method of phishing as it is attempting to farm seed phrases. In the February attack, the hacker did not attempt to compromise a victim's seed phrase but instead tricked the victim into signing permissions allowing for the transfer of NFTs to the exploiter. The important takeaway here is that there are two types of phishing attacks in Web3.

  1. Classic phishing - Getting a user to send funds to or trick them in to giving away private keys / seed phrases
  2. Ice phishing - Trick a victim into giving a malicious actor approval to transfer assets by signing a transaction.

The OpenSea phishing attack in February falls under the second category and was one of the main methods used to steal users NFTs.

NFTs & Phishing

NFTs have been an attractive target for scammers this year with persistent threat actors targeting projects Discord servers. So far in 2022, we have detected over 730 Discord compromises that have targeted NFT holders. The vast majority of exploits tricked users into signing approvals allowing the attacker to transfer NFTs from the victims to the exploiter.

ncidents of this sort decreased dramatically after detailed investigations uncovered the threat actor responsible for the majority of these compromises. You can read more about the connections between these hacks in our detailed analysis.

Conclusion

NFT holders were a lucrative target for illicit actors in 2022. Users need to be aware that their wallets do not necessarily have to be compromised for their assets to be stolen. In the case of the OpenSea phishing attack, and the majority of phishing attacks, the victims have been tricked in to signing approvals to the attacker. This is why NFT holders need to take special care in verifying that communications are from trusted sources. By following @CertiKAlert on Twitter, you’ll be the first to be alerted on compromises in the NFT space to better help you understand the threats that are out there.

Appendix

List of phished NFTs stolen in the OpenSea phishing attack.

NFT
Comments

All Comments

Recommended for you

  • Besenet: Inflation Will Return to Target Levels, Fed Chair Waller to Optimize Growth and Price Stability Path

    On June 24, U.S. Treasury Secretary Besenet stated that inflation will return to target levels, and Fed Chair Waller will optimize the path for growth and price stability. Trump and I understand the power of the bond market and have already seen the economic growth brought by artificial intelligence. (Sina Finance)

  • US Spot Ethereum ETF Sees Net Outflow of $82.18 Million

    On June 24, according to monitoring by Trader T, the US spot Ethereum ETF experienced a net outflow of $82.18 million yesterday.

  • US Spot Bitcoin ETF Sees Net Outflow of $113.79 Million Yesterday

    On June 24, according to monitoring by Trader T, the US spot Bitcoin ETF experienced a net outflow of $113.79 million yesterday.

  • BTC Surpasses $63,000

    Market data shows that BTC has surpassed $63,000, currently priced at $63,003.99, with a 24-hour decline of 1.47%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $63,000

    Market data shows that BTC has surpassed $63,000, currently priced at $63,006.88, with a 24-hour decline of 1.52%. The market is highly volatile, so please ensure proper risk management.

  • Zuckerberg Directs Meta to Develop Prediction Market Application

    On June 24, The New York Times reported that Zuckerberg has instructed Meta to develop a prediction market application. The internal name for the application is 'Arena', which is similar to Polymarket or Kalshi.

  • U.S. Senate Passes Resolution Aiming to Limit Trump's War Powers Against Iran

    On June 24, the U.S. Senate passed a resolution regarding war powers related to Iran, with 50 votes in favor and 48 against, following a similar approval by the House of Representatives. This marks the first time such a resolution has been approved by both chambers of Congress. The resolution calls for the president to end military actions against Iran without a declaration of war or authorization of force from Congress. However, since this resolution is a joint resolution of Congress, it is not legally binding and does not require the president's signature, thus serving mainly a symbolic purpose.

  • AI Smart Terminals Experience Full Explosion

    On June 23, according to CCTV Finance, at the fourth Chain Expo, the original "Digital Technology Chain" was upgraded to the "Smart Technology Chain." This change in wording reflects that artificial intelligence is becoming the main character in the industrial chain. A newly established AI zone at the event gathered leading AI companies from both domestic and international markets, showcasing the entire chain from data and computing power to applications. Various AI products were on display, including AI glasses, smart cars with digital chassis, and humanoid robots that can play soccer. CCTV Finance reporters observed that the integration of artificial intelligence into the physical world is transitioning from mobile phones and computers to various new smart terminals. This year, the application of AI agents has also experienced a full explosion. Qian Kun, Senior Vice President of Qualcomm, stated that the empowerment of AI agents is leading to a significant upgrade cycle for existing terminal devices. China's industrial chain is very complete, and through continuous collaboration with Chinese partners, their products can quickly reach the market and gain global acceptance. Liu Xiangwen, Vice President of Alibaba Cloud Intelligence Group, noted that AI has evolved from mere chatting to becoming a productive force. The development of all stacks, whether GPU cloud or CPU, is progressing rapidly, and there is still greater potential ahead.

  • U.S. Stock Indices Experience Short-Term Rally

    On June 23, the Dow Jones Industrial Average rose by 0.07%; the S&P 500 index narrowed its decline to 0.77%, having previously fallen over 1.5%; the Nasdaq Composite index also reduced its drop to 1.17%, after having been down more than 2.3% at one point.

  • Vitalik: Ethereum Foundation Budget Cut by 40%, Shifting to Long-term Fund Model

    On June 23, Vitalik Buterin revealed that the Ethereum Foundation (EF) will reduce its budget by approximately 40% this year. According to its previously announced financial management plan, EF is transitioning from a model where it spends about 15% of its remaining funds annually to a model where it will spend about 5% annually after 2030, moving towards a long-term donation-oriented organization. To this end, EF will adjust its multi-client model, relying more on AI-assisted formal verification. The PSE privacy and scalability exploration team will shift from 'exploration' to a focus on building around zero-knowledge proofs. The scale and losses of Devcon events will be reduced, and large projects beyond Ethereum itself will also decrease. EF's institutional work will focus on smaller-scale, replicable CROPS-friendly deployment cases.